PERANCANGAN DAN IMPLEMENTASI SISTEM DETEKSI DAN MANAJEMEN INSIDEN KEAMANAN SIBER BERBASIS LOG AUTENTIKASI SSO PADA PT. XYZ
| dc.contributor.advisor | Haikal, Antoni | |
| dc.contributor.author | Simanjuntak, Vincentius | |
| dc.date.accessioned | 2026-08-24T07:59:35Z | |
| dc.date.issued | 2026-09-09 | |
| dc.description.abstract | The advancement of information technology has driven the widespread adoption of Single Sign-On (SSO) as a centralized authentication solution, making it a prime target for attacks such as brute force and credential stuffing. This study proposes the design and implementation of a cybersecurity incident detection and management system based on Keycloak SSO authentication log analysis. The system integrates four main components: Keycloak as the SSO provider, Redis for alert deduplication and temporary storage, TheHive as the incident management platform, and n8n for workflow automation. Threat detection is performed by a Python worker that continuously reads Keycloak LOGIN_ERROR logs and compares them against defined security rules—brute force and credential stuffing detection. A deduplication mechanism using Redis prevents duplicate incident tickets from being created in TheHive. Experimental testing with simultaneous attack injection from two IP addresses across eight simulation scenarios showed that the system achieved 100% detection accuracy for both attack types. The deduplication mechanism successfully ensured only one unique incident case was created per attacker entity per day. The average end-to-end processing time from alert detection to case creation in TheHive was 2.937 seconds. These results demonstrate that the proposed architecture effectively automates security monitoring, alert deduplication, and incident ticket creation in an efficient and structured manner. | |
| dc.identifier.citation | IEEE | |
| dc.identifier.kodeprodi | KODEPRODI57302#Rekayasa_Keamanan_Siber | |
| dc.identifier.nidn | NIDN8942560023 | |
| dc.identifier.nim | NIM4332211002 | |
| dc.identifier.uri | https://repository.polibatam.ac.id//handle/PL29/5862 | |
| dc.language.iso | other | |
| dc.publisher | Politeknik Negeri Batam | |
| dc.subject | Single Sign-On | |
| dc.subject | Keycloak | |
| dc.subject | brute force | |
| dc.subject | credential stuffing | |
| dc.subject | log analysis | |
| dc.subject | Redis | |
| dc.subject | TheHive | |
| dc.subject | incident | |
| dc.subject | management | |
| dc.subject | deduplication | |
| dc.title | PERANCANGAN DAN IMPLEMENTASI SISTEM DETEKSI DAN MANAJEMEN INSIDEN KEAMANAN SIBER BERBASIS LOG AUTENTIKASI SSO PADA PT. XYZ | |
| dc.title.alternative | DESIGN AND IMPLEMENTATION OF A LOG-BASED CYBERSECURITY INCIDENT DETECTION AND MANAGEMENT SYSTEM FOR SSO AUTHENTICATION AT PT. XYZ | |
| dc.type | Article |
Files
Original bundle
1 - 3 of 3
Loading...
- Name:
- 4332211002_Artikel.pdf
- Size:
- 4.25 MB
- Format:
- Adobe Portable Document Format
- Description:
- Full Page Artikel
Loading...
- Name:
- Lembar_Pengesahan.pdf
- Size:
- 123.44 KB
- Format:
- Adobe Portable Document Format
- Description:
- Lembar Pengesahan
Loading...
- Name:
- Borang_Publikasi.pdf
- Size:
- 168.26 KB
- Format:
- Adobe Portable Document Format
- Description:
- Borang Publikasi
License bundle
1 - 1 of 1
Loading...
- Name:
- license.txt
- Size:
- 1.71 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
